Your biggestrisk alreadyhas a login.

We make sure people only have the access they need, and lose it the day they leave. That goes for employees, admins and service accounts, with an audit trail ready for NIS2 and DORA.

Take the 60-second check
01 · The door nobody closed
0+years of combined identity & access expertise
24/7remote helpdesk & managed IAM operations
0kusers per IGA tenant, ready to run
EUcompany, EU data, EU-nearshore engineering
Identity exposure check

Six questions your auditor will ask. So will an attacker.

Be honest. Your answers stay in your browser.

    The European clock

    Since NIS2 and DORA, who has access is a board-level question.

    Directive (EU) 2022/2555In force

    NIS2

    Essential and important entities have to manage cyber risk, and their directors are personally accountable.

    • Access control & asset policies
    • Multi-factor authentication
    • HR security: joiners, movers, leavers
    Regulation (EU) 2022/2554Applies since Jan 2025

    DORA

    Banks, insurers and their ICT suppliers have to be able to prove who has access to what.

    • Least privilege & strong authentication
    • Privileged access under control
    • Evidence on demand for supervisors
    Regulation (EU) 2024/1689Phasing in

    AI Act

    Companies are giving AI agents access to real systems. Each agent is an identity, and somebody has to own it.

    • Machine & agent identities governed
    • Human oversight of access
    • Traceable, logged decisions
    AI agents · non-human identities · 03:12

    Your newest colleagues aren’t human. Nobody onboarded them.

    AI agents read your mail, move money, open tickets and change systems. Each one logs in. Most have more access than any employee, no owner, and no end date.

    0doors opened by one agent tonight
    Scale0 : 1

    Machine identities per human in the average organisation. Agents are the fastest-growing group.1

    Damage0%

    of organisations hit by an AI-related breach had no proper access controls on their AI.2

    Deadline2 Dec 2027

    High-risk AI Act rules apply. Human oversight and logging have to be provable. NIS2 and DORA already cover these accounts today.3

    An open AI agent passport for invoice-agent-07 with owner, purpose, access, credential and review fields, stamped Cleared
    The answer

    Give every agent a passport.

    One record per agent: owner, purpose, allowed actions, credential, expiry and review. The rule is simple. No passport, no access.

    How a passport is issued

    No passport, no access.

    1. 01
      Register

      Every agent gets a named human owner and a purpose. Nobody wants to sign for it? Then it gets switched off.

    2. 02
      Scope

      The passport lists the allowed systems and actions. Nothing more, and no standing admin rights.

    3. 03
      Lock the keys

      No passwords or API keys in code. Short-lived tokens from a vault, rotated automatically.

    4. 04
      Watch and approve

      Every action is logged against the passport. Payments, deletions and data exports wait for a human.

    5. 05
      Expire

      Every passport has an end date. The owner renews it at review, or the agent stops.

    Agent passportIssued under ESCUR governance
    No passport
    invoice-agent-07
    Owner
    unknownFinance · J. de Vries
    Purpose
    unknownMatch supplier invoices to POs
    Access
    ERP admin · mailbox · file sharesERP: read invoices, draft entries
    Credential
    API key in code · created 2024Vaulted token · expires in 1h
    Oversight
    noneLogged · payments need approval
    Expiry
    neverRenew at review, every 90 days
    RiskHigh
    Enforcement

    Checked at every border.

    Wherever the agent runs, it has to show its passport.

    01 · In your cloudIdentity sidecar

    Sits next to each agent you build. Short-lived tokens, and one switch to cut it off.

    02 · In your SaaSApp permissions

    Copilot, Agentforce, ServiceNow. Their permissions follow the passport and are revoked centrally.

    03 · At every tool callPolicy gateway

    MCP servers and APIs are checked against the passport. Payments wait for a human.

    Agent Passport Sprint

    We find every agent, issue a passport for each one, and flag the ones nobody will sign for. Those are the first to switch off.

    Why ESCUR. The passports live in One Identity, with the same joiner, mover, leaver and review discipline we’ve run for tens of thousands of human identities. Governance and enforcement from one place, run from the EU.

    Start your Agent Passport Sprint
    1. Palo Alto Networks, 2026 Identity Security Landscape
    2. IBM, Cost of a Data Breach 2025
    3. European Commission, AI Omnibus in force (27 July 2026) · risk model: OWASP Top 10 for Agentic Applications, OWASP NHI Top 10
    What we do

    Six things we do. Most clients start with the first.

    How we work

    Four steps. Usually in this order.

    01

    Discover

    Find every account, including the ones nobody remembers creating.

    02

    Govern

    Automate joiner-mover-leaver, roles and recertification on One Identity.

    03

    Protect

    Vault privileged access, record sessions, stop sensitive data leaving.

    04

    Run

    We run it 24/7 and pull the audit evidence whenever you need it.

    Why ESCUR

    “Most breaches I’ve seen didn’t need a genius. They needed one account nobody switched off.”

    Melvis Hadžić, founder and CEO of ESCUR
    Melvis HadžićFounder & CEO, ESCUR
    Amel Hadžić, Senior IAM Developer
    1. Early careerBHOLD functional consultant

      Role management and process-driven authorisation.

    2. OraclePrincipal Sales Consultant, IAM

      Identity & role management across Western Continental Europe.

    3. European Identity ConferenceSpeaker, KuppingerCole EIC

      Best practice in IAM implementation and delivery.

    4. TodayESCUR, identity security as a service

      One Identity Silver Partner. Forcepoint partner. EU-based.

    PartnerOne Identity

    Silver Partner for Identity Manager and Safeguard.

    PartnerForcepoint

    Data Loss Prevention & DSPM.

    CloudMicrosoft Azure

    IGA foundation hosted and run on Azure.

    BURGAS SARAJEVO NETHERLANDS
    1. 01 · HeadquartersBurgas, EU

      ESCUR Ltd, registered in Bulgaria.

    2. 02 · EngineeringSarajevo

      Senior IAM developers, one time zone from you.

    3. 03 · ClientsNetherlands & EU

      Where most of our clients are.

    Morning, as it should be

    Sleep through 03:12.

    Half an hour on a call. We’ll look at where your identity risk is and what your auditor is likely to ask first.